Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
398,853 CVEs1,728 in CISA KEV17,267 with EPSS ≥ 10%25,049 with a public exploitUpdated 28 September 2026
25,049 results · page 360 of 501
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2007-0267 | The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted… | EXPLOIT ✓MEDIUM 6.6EPSS 0.95% | 17 January 2007 |
| CVE-2006-6938 | Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote attackers to include arbitrary files via ".." sequences in the root parameter. | EXPLOIT ✓MEDIUM 5.0EPSS 3.00% | 17 January 2007 |
| CVE-2006-6937 | SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 17 January 2007 |
| CVE-2006-6936 | Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or web script via (1) the catname parameter to displaypic.asp or (2) the search field. | EXPLOIT ✓MEDIUM 6.8EPSS 1.79% | 17 January 2007 |
| CVE-2007-0264 | Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument. | EXPLOIT ✓MEDIUM 6.6EPSS 0.70% | 16 January 2007 |
| CVE-2007-0261 | snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by… | EXPLOIT ✓HIGH 10.0EPSS 4.75% | 16 January 2007 |
| CVE-2007-0257 | Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. | EXPLOIT ✓HIGH 7.8EPSS 1.00% | 16 January 2007 |
| CVE-2007-0256 | VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file. | EXPLOIT ×2 ✓HIGH 7.8EPSS 11.9% | 16 January 2007 |
| CVE-2006-6932 | Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp. | EXPLOIT ×2 ✓HIGH 7.5EPSS 1.03% | 16 January 2007 |
| CVE-2006-6767 | oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV command with an unsupported address family, which triggers an assertion failure. | EXPLOIT ✓HIGH 7.5EPSS 6.80% | 16 January 2007 |
| CVE-2006-6487 | Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the error[] parameter. | EXPLOIT ✓MEDIUM 5.1EPSS 2.21% | 16 January 2007 |
| CVE-2007-0247 | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions. | EXPLOIT ✓MEDIUM 5.0EPSS 19.7% | 16 January 2007 |
| CVE-2007-0236 | Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that… | EXPLOIT ✓HIGH 10.0EPSS 21.4% | 16 January 2007 |
| CVE-2007-0235 | Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its… | EXPLOIT ✓LOW 3.7EPSS 0.89% | 16 January 2007 |
| CVE-2007-0233 | wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL… | EXPLOIT ✓HIGH 7.5EPSS 11.6% | 13 January 2007 |
| CVE-2007-0232 | PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the jssShopFileSystem parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.34% | 13 January 2007 |
| CVE-2007-0229 | Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a… | EXPLOIT ✓HIGH 7.2EPSS 1.10% | 13 January 2007 |
| CVE-2007-0228 | The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8)… | EXPLOIT ✓MEDIUM 5.0EPSS 7.57% | 13 January 2007 |
| CVE-2007-0226 | SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter). | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 13 January 2007 |
| CVE-2007-0225 | Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 1.82% | 13 January 2007 |
| CVE-2007-0224 | SQL injection vulnerability in shopgiftregsearch.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginLastname parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.09% | 13 January 2007 |
| CVE-2006-6930 | SQL injection vulnerability in viewad.asp in Rapid Classified 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.26% | 13 January 2007 |
| CVE-2006-6929 | Multiple cross-site scripting (XSS) vulnerabilities in Rapid Classified 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) reply.asp or (b) view_print.asp, the (2) SH1 parameter to (c) search.asp, the (3)… | EXPLOIT ×4 ✓MEDIUM 6.8EPSS 2.20% | 13 January 2007 |
| CVE-2006-6928 | Multiple cross-site scripting (XSS) vulnerabilities in Rialto 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to (a) listmain.asp or (b) searchmain.asp, the (2) the Keyword parameter to (c) searchkey.asp, or… | EXPLOIT ×4 ✓MEDIUM 6.8EPSS 2.13% | 13 January 2007 |
| CVE-2006-6927 | Multiple SQL injection vulnerabilities in Rialto 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the uname (username) and (2) pword (passwd) fields in (a) admin/default.asp; the (3) ID parameter to (b) listfull.asp or (c)… | EXPLOIT ×7 ✓HIGH 7.5EPSS 1.23% | 13 January 2007 |
| CVE-2006-6925 | Multiple cross-site scripting (XSS) vulnerabilities in bitweaver 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the message title field when submitting an article to articles/edit.php, (2) the message title field… | EXPLOIT ✓MEDIUM 6.8EPSS 2.14% | 13 January 2007 |
| CVE-2006-6924 | bitweaver 1.3.1 and earlier allows remote attackers to obtain sensitive information via a sort_mode=-98 query string to (1) blogs/list_blogs.php, (2) fisheye/index.php, (3) wiki/orphan_pages.php, or (4) wiki/list_pages.php, which forces a SQL error. | EXPLOIT ×4 ✓MEDIUM 5.0EPSS 3.41% | 13 January 2007 |
| CVE-2006-6923 | SQL injection vulnerability in newsletters/edition.php in bitweaver 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the tk parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.08% | 13 January 2007 |
| CVE-2007-0190 | PHP remote file inclusion vulnerability in edit_address.php in edit-x ecommerce allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 12 January 2007 |
| CVE-2007-0183 | Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 3.95% | 12 January 2007 |
| CVE-2007-0182 | Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3)… | EXPLOIT ×28 ✓HIGH 7.5EPSS 4.64% | 12 January 2007 |
| CVE-2006-6919 | Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element… | EXPLOIT ✓MEDIUM 6.8EPSS 2.17% | 11 January 2007 |
| CVE-2007-0205 | Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. | EXPLOIT ✓HIGH 7.5EPSS 3.34% | 11 January 2007 |
| CVE-2007-0169 | Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allow remote attackers to execute arbitrary code via RPC requests with crafted data… | EXPLOIT ✓HIGH 7.5EPSS 70.0% | 11 January 2007 |
| CVE-2007-0168 | The Tape Engine service in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10.5, and CA Server/Business Protection Suite r2 allows remote attackers to execute arbitrary code via certain data in opnum 0xBF in an… | EXPLOIT ✓HIGH 7.5EPSS 19.9% | 11 January 2007 |
| CVE-2007-0202 | SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lang parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.80% | 11 January 2007 |
| CVE-2007-0200 | PHP remote file inclusion vulnerability in template.php in Geoffrey Golliher Axiom Photo/News Gallery (axiompng) 0.8.6 allows remote attackers to execute arbitrary PHP code via a URL in the baseAxiomPath parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.31% | 11 January 2007 |
| CVE-2007-0197 | Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption. | EXPLOIT ✓MEDIUM 6.8EPSS 8.13% | 11 January 2007 |
| CVE-2007-0196 | SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. | EXPLOIT ✓HIGH 7.5EPSS 1.21% | 11 January 2007 |
| CVE-2007-0181 | PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.34% | 11 January 2007 |
| CVE-2007-0179 | SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter. | EXPLOIT ✓HIGH 7.5EPSS 1.06% | 11 January 2007 |
| CVE-2007-0178 | PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.66% | 11 January 2007 |
| CVE-2007-0177 | Cross-site scripting (XSS) vulnerability in the AJAX module in MediaWiki before 1.6.9, 1.7 before 1.7.2, 1.8 before 1.8.3, and 1.9 before 1.9.0rc2, when wgUseAjax is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified… | EXPLOIT ✓MEDIUM 5.1EPSS 3.44% | 11 January 2007 |
| CVE-2007-0173 | Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enabled and magic_quotes is disabled, allows remote attackers to include and execute arbitrary local files via a .. | EXPLOIT ✓MEDIUM 6.8EPSS 2.58% | 11 January 2007 |
| CVE-2007-0172 | Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in… | EXPLOIT ✓HIGH 7.5EPSS 4.98% | 11 January 2007 |
| CVE-2007-0171 | PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AML_opensite parameter. | EXPLOIT ✓HIGH 7.5EPSS 3.29% | 11 January 2007 |
| CVE-2007-0170 | PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary PHP code via a URL in the AMV_serverpath parameter. | EXPLOIT ✓HIGH 7.5EPSS 2.38% | 11 January 2007 |
| CVE-2007-0167 | Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow remote attackers to execute arbitrary PHP code via a URL in the INC parameter in (1) config_admin.php, (2) config_main.php, (3)… | EXPLOIT ✓HIGH 7.5EPSS 10.3% | 10 January 2007 |
| CVE-2007-0165 | Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind. | EXPLOIT ✓HIGH 7.8EPSS 9.65% | 10 January 2007 |
| CVE-2007-0162 | Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or… | EXPLOIT ✓MEDIUM 6.8EPSS 0.83% | 10 January 2007 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.